Privacy Architecture

Privacy Policy

BELFI65 — AI-Powered Veterinary Diagnostic Platform & Guardian Pet Health

Effective Date: January 2026 | Last Updated: June 2026

Our Commitment

BELFI65 ("we," "our," or "us") is committed to protecting your privacy and the confidentiality of your clients' information. This Privacy Policy explains how we collect, use, store, and protect data when you use our AI-powered veterinary diagnostic platform and the BELFI65 Guardian pet owner health portal.

By using BELFI65, you agree to the practices described in this policy. We voluntarily implement HIPAA-equivalent technical safeguards, ensuring that all veterinary patient and client data is protected using the same infrastructure standards required in human healthcare.

1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address and name
  • Practice name and professional credentials
  • Subscription and billing information (payment details are processed securely by our PCI-DSS certified payment processor and are never stored on our servers)

Clinical Data (Veterinary Platform)

When you use our diagnostic services, we process:

  • Patient (animal) information: species, breed, age, weight, and clinical signs
  • Laboratory results, vital signs, and medical history
  • Radiographs, clinical photographs, and other diagnostic images
  • AI-generated diagnostic analyses and treatment recommendations

Guardian Pet Health Data (Pet Owner Portal)

When pet owners use BELFI65 Guardian, we collect and store:

  • Pet profiles: name, species, breed, date of birth, weight
  • Health records: vitals, lab results, vaccines, medications, genomics
  • Owner observations: free-text symptom notes (including voice-transcribed observations)
  • Health photos: EXIF metadata stripped client-side before upload; only compressed image content stored
  • Vet visit records and follow-up notes entered by the owner

2. How We Use Your Information

We use the information we collect to:

  • Provide AI-powered diagnostic analysis
  • Support VCPR documentation requirements
  • Maintain State Veterinary Board compliance logs
  • Generate specialist consultation perspectives
  • Create client education materials
  • Process payments and manage subscriptions
  • Improve our services and develop new features
  • Generate Guardian health intelligence observations

We do not sell, rent, or share your personal or clinical data with third parties for marketing purposes.

3. Data Security

We implement comprehensive security measures to protect your data:

AES-256 Encryption SOC 2 Type II PCI-DSS Compliant TLS 1.3

Encryption Protocols

  • AES-256 at rest: All stored data is protected with military-grade encryption
  • TLS 1.3 in transit: All data transmitted between your device and our servers is encrypted

Access Controls

  • Row-Level Security: Database policies ensure you can only access your own data
  • JWT Authentication: Cryptographically signed tokens verify your identity

4. Data Sharing and Third Parties

We share data only with categorical service providers bound by strict confidentiality agreements:

AI Processing

Data is processed in ephemeral sandboxes. It is not used for model training.

Payment Processors

PCI-DSS Level 1 certified processors handle all transactions.

Infrastructure

SOC 2 compliant cloud services host our platform.

6. Your Rights

You have the following rights regarding your data:

  • Access
  • Correction
  • Deletion
  • Export
  • Withdraw Consent

7. BELFI65 Guardian — Pet Owner Data

BELFI65 Guardian is a separate product layer for pet owners. This section describes how we handle data collected through the Guardian portal specifically. Guardian data is stored separately from veterinary clinical data and governed by its own access controls.

What Guardian Data We Collect

Pet profiles

Name, species, breed, date of birth, weight

Health records

Vitals, labs, vaccines, medications, genomic data you enter

Health photos

Compressed images with EXIF metadata stripped before upload

Voice observations

Audio processed ephemerally — only extracted text is stored, never the audio

Owner observations

Free-text symptom notes you enter about your pet

Health intelligence

AI-generated observations from your pet's combined data

Population Benchmarking & Data Consent

BELFI65 is building an anonymised population health database to enable breed-level benchmarking — so owners can see how their pet compares to others of the same species, breed, and age group. This is entirely optional and requires your explicit consent.

If you consent to contribute

  • Vitals trends as anonymised numerical ranges
  • Lab parameter values as aggregated ranges
  • Species, breed, and age range (not exact date of birth)
  • Wellness score patterns

Never shared regardless of consent

  • Your pet's name or your identity
  • Owner name, email, or contact details
  • Location data of any kind
  • Photos or images
  • Voice recordings
  • Full medication names or diagnoses

Consent version and timestamp are stored. You can withdraw consent at any time from the Guardian Settings tab. All previously contributed data will be removed from the analytics pipeline within 30 days of withdrawal.

Guardian Data Isolation

Guardian pet health records are stored in dedicated tables with row-level security policies tied to the owner's user ID. No veterinary CDSS user can access Guardian pet data. No Guardian user can access veterinary clinical records. The two product layers are architecturally isolated at the database level.

Your Guardian Data Rights

Access

Download all your pet's health data

Correction

Edit or correct any record

Deletion

Delete any record or your entire account

Withdraw consent

Opt out of population analytics at any time

8. BELFI65 Guardian — Trust Architecture

This section details the specific technical and architectural measures in place for the Guardian pet owner portal, so you can make an informed decision about storing your pet's health data with BELFI65.

Where your data lives

  • Stored on Supabase (PostgreSQL) with AES-256 encryption at rest
  • Hosted in data centres with SOC 2 Type II certification
  • Photos stored in private storage buckets — not publicly accessible
  • Signed URLs generated per-session for photo access (1-hour expiry)

AI processing (Gemini API)

  • Health analysis requests processed ephemerally — no data persists after the request
  • Gemini API is not used to train models on your pet's data
  • Chat messages are not stored on Google's servers
  • Voice observations: audio processed ephemerally, only extracted text is saved

Photo privacy

  • EXIF metadata (location, device info, timestamps) stripped client-side before upload
  • Images compressed to 1800px maximum before leaving your device
  • Stored in isolated per-user folders — no cross-user access
  • Permanently deleted from storage when you delete the photo record

Voice observations

  • Audio recorded in-browser and sent directly to a secure edge function
  • Audio is never stored — only the extracted plain-text observation is saved
  • Processing is multilingual — your language is detected and translated to English
  • Edge function runs in an ephemeral Deno runtime — no persistent compute

Access control

  • Row-Level Security enforced at the database level — not just application logic
  • Your pet data is accessible only by your authenticated user ID
  • Veterinary users cannot access Guardian data even if they share an email domain
  • API keys and tokens are never stored in plain text

Population analytics pipeline

  • Only runs on records where data_consent = true
  • De-identification removes pet name, owner ID, and exact dates before aggregation
  • Only statistical ranges are stored in population tables — never raw records
  • Consent version and timestamp recorded for audit trail

AI model training disclosure

BELFI65 does not use your pet's health data to train AI models — including the Gemini API models used for health intelligence and chat. Your data is used solely to generate responses for your session. This applies to both the veterinary CDSS and the Guardian pet owner portal.

Questions about
your privacy?

Our dedicated privacy team is available to discuss our data orchestration, Guardian data handling, and clinical isolation protocols.